Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Molkobain

#15519of 53,633
17.5Total CVSS
Vulnerabilities · 2
High
2
PT-2024-13463
8.8
2024-01-04
Itop · Itop · CVE-2023-47626
**Name of the Vulnerable Software and Affected Versions** iTop versions prior to 3.1.1 **Description** The issue concerns an IT service management platform where XSS attacks are possible when displaying or editing a user's personal tokens. **Recommendations** For versions prior to 3.1.1, update to version 3.1.1 to resolve the issue.
PT-2022-16942
8.7
2022-04-21
Comodo · Combodo Itop · CVE-2022-24870
**Name of the Vulnerable Software and Affected Versions** Combodo iTop versions 3.0.0 beta through 3.0.0 beta2 **Description** Combodo iTop is a web-based IT Service Management tool. A malicious script can be injected in tooltips using the iTop customization mechanism, providing a stored cross-site scripting attack vector to authorized users of the system. **Recommendations** For versions 3.0.0 beta through 3.0.0 beta2, upgrade to a version newer than 3.0.0 beta2 to resolve the issue. As a temporary workaround, consider restricting the use of the iTop customization mechanism to minimize the risk of exploitation.